Drupal Core DRUPAL-SA-CORE-2018-001 Multiple Security Vulnerabilities
BID:103117
Info
Drupal Core DRUPAL-SA-CORE-2018-001 Multiple Security Vulnerabilities
| Bugtraq ID: | 103117 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2018 12:00AM |
| Updated: | Feb 21 2018 12:00AM |
| Credit: | Anders Olsson, will c, and David Rothstein of the Drupal Security Team |
| Vulnerable: |
Drupal Drupal 7.9 Drupal Drupal 7.8 Drupal Drupal 7.6 Drupal Drupal 7.56 Drupal Drupal 7.55 Drupal Drupal 7.54 Drupal Drupal 7.52 Drupal Drupal 7.5 Drupal Drupal 7.44 Drupal Drupal 7.43 Drupal Drupal 7.42 Drupal Drupal 7.41 Drupal Drupal 7.40 Drupal Drupal 7.4 Drupal Drupal 7.39 Drupal Drupal 7.38 Drupal Drupal 7.37 Drupal Drupal 7.36 Drupal Drupal 7.35 Drupal Drupal 7.34 Drupal Drupal 7.33 Drupal Drupal 7.32 Drupal Drupal 7.31 Drupal Drupal 7.30 Drupal Drupal 7.3 Drupal Drupal 7.29 Drupal Drupal 7.28 Drupal Drupal 7.27 Drupal Drupal 7.26 Drupal Drupal 7.25 Drupal Drupal 7.24 Drupal Drupal 7.23 Drupal Drupal 7.22 Drupal Drupal 7.21 Drupal Drupal 7.20 Drupal Drupal 7.2 Drupal Drupal 7.19 Drupal Drupal 7.18 Drupal Drupal 7.17 Drupal Drupal 7.16 Drupal Drupal 7.15 Drupal Drupal 7.14 Drupal Drupal 7.13 Drupal Drupal 7.12 Drupal Drupal 7.11 Drupal Drupal 7.10 Drupal Drupal 7.1 Drupal Drupal 7.0 |
| Not Vulnerable: |
Drupal Drupal 7.57 |
Discussion
Drupal Core DRUPAL-SA-CORE-2018-001 Multiple Security Vulnerabilities
Drupal is prone to multiple security vulnerabilities.
Successfully exploiting these issues may allow an attacker to bypass certain security restrictions and perform unauthorized actions or inject arbitrary links to different pages within the application. This may allow an attacker to perform phishing attacks by presenting false information that may appear to be legitimate application pages..
Drupal core 7.x versions prior to 7.57 are vulnerable.
Drupal is prone to multiple security vulnerabilities.
Successfully exploiting these issues may allow an attacker to bypass certain security restrictions and perform unauthorized actions or inject arbitrary links to different pages within the application. This may allow an attacker to perform phishing attacks by presenting false information that may appear to be legitimate application pages..
Drupal core 7.x versions prior to 7.57 are vulnerable.
Exploit / POC
Drupal Core DRUPAL-SA-CORE-2018-001 Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Drupal Core DRUPAL-SA-CORE-2018-001 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Drupal Core DRUPAL-SA-CORE-2018-001 Multiple Security Vulnerabilities
References:
References:
- Drupal 7.57 Release Notes (Drupal)
- Drupal Homepage (Drupal)
- Drupal core - Critical - Multiple Vulnerabilities - SA-CORE-2018-001 (Drupal)